I worked on the incident-management chain across Microsoft Sentinel, ServiceNow Security Incident Response and XSOAR. Analysts needed the same incident to retain its meaning across the SIEM, operational SIR workspace and SOAR workflow: affected entities, investigation context, status and closure all influenced what happened next.
I clarified requirements for alert versus incident ingestion, affected users, observables, ATT&CK mappings and operational labels. I also worked through linked and redirected incidents so the integration could represent relationships and escalation decisions, as well as individual records.
For closure handling, I defined scenarios in both directions, created and closed controlled incidents, inspected the resulting classifications and logs, and retested after configuration changes. The test set distinguished true positive, benign positive, false positive and undetermined outcomes.
All nine defined closure scenarios passed in the 27 August 2026 validation session. This gave the team a repeatable acceptance scope for those mappings, alongside separate checks for other integration behaviours. I contributed SOC requirements and testing within the shared MDR delivery programme.
Closer to the work
Incident meaning across platforms
A Sentinel incident contains entities and investigation context that need explicit mappings into ServiceNow SIR and the XSOAR workflow. I clarified affected-user, observable and ATT&CK requirements, together with labels used for escalation, automation, suppression, linking and testing. Closure classifications also needed agreed meanings across the platforms.
Open this detail ↗Bidirectional closure mappings
I designed five Sentinel-to-ServiceNow and four ServiceNow-to-Sentinel closure-code scenarios. I created and closed controlled incidents, reviewed logs and classifications, and repeated checks after changes. The scenarios tested both the direction of propagation and the meaning of the closure outcome.
Open this detail ↗A bounded acceptance result
All nine scenarios were recorded as passing on 27 August 2026. That result applied to the defined closure-code test set in that session. Entity mappings, escalation labels, linked incidents and other lifecycle behaviours retained their own requirements and acceptance checks.
Open this detail ↗Skills established through this work